MSI Radix AXE6600 v781521 Command Injection via dmz Function 漏洞概述 严重性: CRITICAL 发布日期: 8/8/2026 CVE: CVE-2026-71986 CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVSS: 9.3 CVSS v4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 描述: MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges on the underlying system. 影响范围 受影响产品: Radix AXE6600 <= v781521, fixed in v782418 修复方案 修复版本: v782418 参考链接 MSI Vendor Site Fix Version Download 贡献者 Jincheng Wang